downie: The URL accesses a PayPal phishing site hosted on a bot net.
IP addresses 68.63.146.167, 71.138.23.154, 76.122.177.31, 76.244.109.194, 77.103.156.54, 79.78.251.60, 82.1.101.170,
82.1.138.130, 82.37.81.101, 98.209.206.129 were active at Wed, 14 May 2008 17:12:56 +0000 (GMT).
Nameservers
NS3.B546EC5A89.COM [68.45.176.12] response 68.63.146.167, 71.138.23.154, 76.122.177.31, 76.244.109.194, 77.103.156.54,
79.78.251.60, 82.1.101.170, 82.1.138.130, 82.37.81.101, 98.209.206.129 in 185 mSec
were active at the same time
=================================
REGISTRAR PAYCENTER:
Domain CLIENT-RECORDS.COM has been registered with PAYCENTER for fraudulent purposes.
It is being used for a fake PayPal site hosted on a bot net.
Please suspend this domain immediately to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email
address.
=================================
REGISTRAR DNS.COM.CN:
Domain B546EC5A89.COM has been registered with DNS.COM.CN for fraudulent purposes.
It is operating nameservers for phishing sites hosted on a bot net.
Please suspend this domain immediately and remove the nameserver glue records (see
http://spamtrackers.eu/wiki/index.php?title=Registrar_Advice) to prevent further criminal activity.
Please also check for any domains registered using the same (stolen) identity and credit card details, or the same email
address.
=================================
NAMESERVER HOST COMCAST:
Nameservers
NS3.B546EC5A89.COM [68.45.176.12] - response 185 mSec
NS6.B546EC5A89.COM [68.45.176.12]
have been set up on your network to serve addresses for this phishing domain and others.
No legitimate domains use these nameservers.
Please shut them down urgently.
Please close the customer's account.
If possible please also be alert for anyone setting up other nameservers on your network for this domain.
=================================
HOSTS: TELEWEST,NTL,TISCALI,AT&T,COMCAST
IP addresses 68.63.146.167, 71.138.23.154, 76.122.177.31, 76.244.109.194, 77.103.156.54, 79.78.251.60, 82.1.101.170,
82.1.138.130, 82.37.81.101, 98.209.206.129 were running infected computers as part of a botnet at the above time,
serving phishing pages.
=================================